PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-49887 Google CVE debrief

A high-severity CVE-2026-49887 vulnerability exists in Google Android, allowing for local escalation of privilege due to a permissions bypass in maybeRemoveInvalidInstallerPackageName of InstallRepository.kt. This issue requires no additional execution privileges and does not need user interaction for exploitation. The vulnerability affects Google Android versions 16.0 and 17.0, and defenders should assess exposure and prioritize remediation to prevent potential local privilege escalation.

Vendor
Google
Product
Android
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-08
Original CVE updated
2026-09-23
Advisory published
2026-09-08
Advisory updated
2026-09-23

Who should care

Defenders responsible for Google Android deployments, particularly those using versions 16.0 and 17.0, should assess exposure and prioritize remediation to prevent potential local privilege escalation.

Why it matters

CVE-2026-49887 is a high-severity vulnerability in Google Android that allows for local escalation of privilege due to a permissions bypass. Defenders should prioritize verifying and applying patches, assessing exposure, and implementing compensating controls to mitigate potential impacts.

  • Verify and apply patches from Google to prevent exploitation
  • Assess exposure in Android deployments to prioritize remediation
  • Implement compensating controls to mitigate potential local privilege escalation

Technical summary

The vulnerability exists in maybeRemoveInvalidInstallerPackageName of InstallRepository.kt, allowing for local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. The CVSS vector is CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. The vulnerability affects Google Android versions 16.0 and 17.0, and defenders should prioritize verifying and applying patches from Google, assessing exposure in their Android deployments, and implementing compensating controls to mitigate potential local privilege escalation.

Defensive priority

Defenders should prioritize verifying and applying patches from Google, assessing exposure in their Android deployments, and implementing compensating controls to mitigate potential local privilege escalation.

Recommended defensive actions

  • Verify and apply patches from Google for affected Android versions
  • Assess exposure in Android deployments and prioritize remediation
  • Implement compensating controls to mitigate potential local privilege escalation
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its high CVSS score of 7.8, and a Vendor Advisory reference from Google. The vulnerability has been identified in Google Android versions 16.0 and 17.0, and defenders should verify and apply patches from Google to prevent exploitation. The evidence is limited to publicly available sources, and further verification is recommended.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-49887 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-49887

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-49887 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-49887

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.